CVE Vulnerabilities

CVE-2011-1575

Published: May 23, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a plaintext command injection attack, a similar issue to CVE-2011-0411.

Affected Software

NameVendorStart VersionEnd Version
Pure-ftpdPureftpd*1.0.29 (including)
Pure-ftpdPureftpd0.90 (including)0.90 (including)
Pure-ftpdPureftpd0.91 (including)0.91 (including)
Pure-ftpdPureftpd0.92 (including)0.92 (including)
Pure-ftpdPureftpd0.93 (including)0.93 (including)
Pure-ftpdPureftpd0.94 (including)0.94 (including)
Pure-ftpdPureftpd0.95 (including)0.95 (including)
Pure-ftpdPureftpd0.95-pre1 (including)0.95-pre1 (including)
Pure-ftpdPureftpd0.95-pre2 (including)0.95-pre2 (including)
Pure-ftpdPureftpd0.95-pre3 (including)0.95-pre3 (including)
Pure-ftpdPureftpd0.95-pre4 (including)0.95-pre4 (including)
Pure-ftpdPureftpd0.95.1 (including)0.95.1 (including)
Pure-ftpdPureftpd0.95.2 (including)0.95.2 (including)
Pure-ftpdPureftpd0.96 (including)0.96 (including)
Pure-ftpdPureftpd0.96.1 (including)0.96.1 (including)
Pure-ftpdPureftpd0.96pre1 (including)0.96pre1 (including)
Pure-ftpdPureftpd0.97-final (including)0.97-final (including)
Pure-ftpdPureftpd0.97.1 (including)0.97.1 (including)
Pure-ftpdPureftpd0.97.2 (including)0.97.2 (including)
Pure-ftpdPureftpd0.97.3 (including)0.97.3 (including)
Pure-ftpdPureftpd0.97.4 (including)0.97.4 (including)
Pure-ftpdPureftpd0.97.5 (including)0.97.5 (including)
Pure-ftpdPureftpd0.97.6 (including)0.97.6 (including)
Pure-ftpdPureftpd0.97.7 (including)0.97.7 (including)
Pure-ftpdPureftpd0.97.7pre1 (including)0.97.7pre1 (including)
Pure-ftpdPureftpd0.97.7pre2 (including)0.97.7pre2 (including)
Pure-ftpdPureftpd0.97.7pre3 (including)0.97.7pre3 (including)
Pure-ftpdPureftpd0.97pre1 (including)0.97pre1 (including)
Pure-ftpdPureftpd0.97pre2 (including)0.97pre2 (including)
Pure-ftpdPureftpd0.97pre3 (including)0.97pre3 (including)
Pure-ftpdPureftpd0.97pre4 (including)0.97pre4 (including)
Pure-ftpdPureftpd0.97pre5 (including)0.97pre5 (including)
Pure-ftpdPureftpd0.98-final (including)0.98-final (including)
Pure-ftpdPureftpd0.98.1 (including)0.98.1 (including)
Pure-ftpdPureftpd0.98.2 (including)0.98.2 (including)
Pure-ftpdPureftpd0.98.2a (including)0.98.2a (including)
Pure-ftpdPureftpd0.98.3 (including)0.98.3 (including)
Pure-ftpdPureftpd0.98.4 (including)0.98.4 (including)
Pure-ftpdPureftpd0.98.5 (including)0.98.5 (including)
Pure-ftpdPureftpd0.98.6 (including)0.98.6 (including)
Pure-ftpdPureftpd0.98.7 (including)0.98.7 (including)
Pure-ftpdPureftpd0.98pre1 (including)0.98pre1 (including)
Pure-ftpdPureftpd0.98pre2 (including)0.98pre2 (including)
Pure-ftpdPureftpd0.99 (including)0.99 (including)
Pure-ftpdPureftpd0.99.1 (including)0.99.1 (including)
Pure-ftpdPureftpd0.99.1a (including)0.99.1a (including)
Pure-ftpdPureftpd0.99.1b (including)0.99.1b (including)
Pure-ftpdPureftpd0.99.2 (including)0.99.2 (including)
Pure-ftpdPureftpd0.99.2a (including)0.99.2a (including)
Pure-ftpdPureftpd0.99.3 (including)0.99.3 (including)
Pure-ftpdPureftpd0.99.4 (including)0.99.4 (including)
Pure-ftpdPureftpd0.99.9 (including)0.99.9 (including)
Pure-ftpdPureftpd0.99a (including)0.99a (including)
Pure-ftpdPureftpd0.99b (including)0.99b (including)
Pure-ftpdPureftpd0.99pre1 (including)0.99pre1 (including)
Pure-ftpdPureftpd0.99pre2 (including)0.99pre2 (including)
Pure-ftpdPureftpd1.0.0 (including)1.0.0 (including)
Pure-ftpdPureftpd1.0.1 (including)1.0.1 (including)
Pure-ftpdPureftpd1.0.2 (including)1.0.2 (including)
Pure-ftpdPureftpd1.0.3 (including)1.0.3 (including)
Pure-ftpdPureftpd1.0.4 (including)1.0.4 (including)
Pure-ftpdPureftpd1.0.5 (including)1.0.5 (including)
Pure-ftpdPureftpd1.0.6 (including)1.0.6 (including)
Pure-ftpdPureftpd1.0.7 (including)1.0.7 (including)
Pure-ftpdPureftpd1.0.8 (including)1.0.8 (including)
Pure-ftpdPureftpd1.0.9 (including)1.0.9 (including)
Pure-ftpdPureftpd1.0.10 (including)1.0.10 (including)
Pure-ftpdPureftpd1.0.11 (including)1.0.11 (including)
Pure-ftpdPureftpd1.0.12 (including)1.0.12 (including)
Pure-ftpdPureftpd1.0.13a (including)1.0.13a (including)
Pure-ftpdPureftpd1.0.14 (including)1.0.14 (including)
Pure-ftpdPureftpd1.0.15 (including)1.0.15 (including)
Pure-ftpdPureftpd1.0.16a (including)1.0.16a (including)
Pure-ftpdPureftpd1.0.16b (including)1.0.16b (including)
Pure-ftpdPureftpd1.0.16c (including)1.0.16c (including)
Pure-ftpdPureftpd1.0.17 (including)1.0.17 (including)
Pure-ftpdPureftpd1.0.17a (including)1.0.17a (including)
Pure-ftpdPureftpd1.0.18 (including)1.0.18 (including)
Pure-ftpdPureftpd1.0.19 (including)1.0.19 (including)
Pure-ftpdPureftpd1.0.20 (including)1.0.20 (including)
Pure-ftpdPureftpd1.0.21 (including)1.0.21 (including)
Pure-ftpdPureftpd1.0.22 (including)1.0.22 (including)
Pure-ftpdPureftpd1.0.24 (including)1.0.24 (including)
Pure-ftpdPureftpd1.0.25 (including)1.0.25 (including)
Pure-ftpdPureftpd1.0.26 (including)1.0.26 (including)
Pure-ftpdPureftpd1.0.27 (including)1.0.27 (including)
Pure-ftpdPureftpd1.0.28 (including)1.0.28 (including)
Pure-ftpdUbuntudapper*
Pure-ftpdUbuntuhardy*
Pure-ftpdUbuntulucid*
Pure-ftpdUbuntumaverick*
Pure-ftpdUbuntunatty*
Pure-ftpdUbuntuupstream*

References